API Key Mismanagement in Claude Code Product
CVE-2026-103012
2LOW
What is CVE-2026-103012?
Claude Code has a vulnerability where an insecure API key may be utilized during a session for organizational settings, even if the user has authenticated correctly via their Enterprise or Team account. When the stored API key is rejected, the session can begin without the organization's policy restrictions, leading to potential security lapses. This issue arises when a device retains a stored API key from previous sessions. Organizations are advised to ensure manual updates to the latest version to mitigate the risks posed by this vulnerability.
Affected Version(s)
@anthropic-ai/claude-code 2.0.68 < 2.1.260
